First published: Fri Nov 17 2017(Updated: )
Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/optipng | 0.7.7-1 0.7.7-2 0.7.7-3 | |
Optipng Project Optipng | =0.7.6 | |
Debian Debian Linux | =7.0 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-1000229 is an integer overflow bug in the function minitiff_read_info() of optipng 0.7.6.
An attacker can remotely execute code or cause denial of service using CVE-2017-1000229.
You can fix CVE-2017-1000229 in optipng 0.7.6 by upgrading to version 0.7.7-1, 0.7.7-2, or 0.7.7-3.
Yes, Optipng Project Optipng 0.7.6 is affected by CVE-2017-1000229.
The severity of CVE-2017-1000229 is high with a CVSS score of 7.8.